📄 PDF — HKICPA Handbook Vol III (Code of Ethics)

Open PDF →" data-zh="不支援PDF檢視。打開PDF →">PDF viewer not supported.

🎥 Video Lesson (Coming Soon)
🎬Glossary of Terms walkthrough video coming soon.

English Section

Overview and Scope

This Glossary of Terms relates to Hong Kong Standards on Quality Control, Auditing, Review, Other Assurance and Related Services. It was issued September 2009 and revised multiple times through December 2021. The glossary is based on the International Glossary of Terms of the International Auditing and Assurance Standards Board (IAASB).

Key Definitions and Explanations:

Access controls - Procedures designed to restrict access to on-line terminal devices, programs and data. Access controls consist of "user authentication" (identifying users through unique logon identifications, passwords, access cards or biometric data) and "user authorization" (access rules determining which computer resources each user may access). These procedures prevent or detect:

  • Unauthorized access to on-line terminal devices, programs and data
  • Entry of unauthorized transactions
  • Unauthorized changes to data files
  • Use of computer programs by unauthorized personnel
  • Use of computer programs that have not been authorized
  • Accounting estimate - A monetary amount for which the measurement, in accordance with the requirements of the applicable financial reporting framework, is subject to estimation uncertainty.

    Accounting records - The records of initial accounting entries and supporting records, such as checks and records of electronic fund transfers; invoices; contracts; the general and subsidiary ledgers, journal entries and other adjustments to the financial statements that are not reflected in formal journal entries; and records such as work sheets and spreadsheets supporting cost allocations, computations, reconciliations and disclosures.

    Agreed-upon procedures engagement - An engagement in which an auditor is engaged to carry out those procedures of an audit nature to which the auditor and the entity and any appropriate third parties have agreed and to report on factual findings. The recipients of the report form their own conclusions from the report by the auditor. The report is restricted to those parties that have agreed to the procedures to be performed since others, unaware of the reasons for the procedures may misinterpret the results.

    Analytical procedures - Evaluations of financial information through analysis of plausible relationships among both financial and non-financial data. Analytical procedures also encompass such investigation as is necessary of identified fluctuations or relationships that are inconsistent with other relevant information or that differ from expected values by a significant amount.

    Annual report - A document, or combination of documents, prepared typically on an annual basis by management or those charged with governance in accordance with law, regulation or custom, the purpose of which is to provide owners (or similar stakeholders) with information on the entity's operations and the entity's financial results and financial position as set out in the financial statements. An annual report contains or accompanies the financial statements and the auditor's report thereon and usually includes information about the entity's developments, its future outlook and risks and uncertainties, a statement by the entity's governing body, and reports covering governance matters.

    Anomaly - A misstatement or deviation that is demonstrably not representative of misstatements or deviations in a population.

    Applicable criteria (in the context of HKSAE 3410) - The criteria used by the entity to quantify and report its emissions in the GHG statement.

    Applicable criteria (in the context of HKSAE 3420) - The criteria used by the responsible party when compiling the pro forma financial information. Criteria may be established by an authorized or recognized standard-setting organization or by law or regulation. Where established criteria do not exist, they will be developed by the responsible party.

    Applicable financial reporting framework - The financial reporting framework adopted by management and, where appropriate, those charged with governance in the preparation of the financial statements that is acceptable in view of the nature of the entity and the objective of the financial statements, or that is required by law or regulation.

    The term "fair presentation framework" is used to refer to a financial reporting framework that requires compliance with the requirements of the framework and:

    (a) Acknowledges explicitly or implicitly that, to achieve fair presentation of the financial statements, it may be necessary for management to provide disclosures beyond those specifically required by the framework; or

    (b) Acknowledges explicitly that it may be necessary for management to depart from a requirement of the framework to achieve fair presentation of the financial statements. Such departures are expected to be necessary only in extremely rare circumstances.

    The term "compliance framework" is used to refer to a financial reporting framework that requires compliance with the requirements of the framework, but does not contain the acknowledgements in (a) or (b) above.

    Application controls in information technology - Manual or automated procedures that typically operate at a business process level. Application controls can be preventative or detective in nature and are designed to ensure the integrity of the accounting records. Accordingly, application controls relate to procedures used to initiate, record, process and report transactions or other financial data.

    Applied criteria (in the context of HKSA 810 (Revised)) - The criteria applied by management in the preparation of the summary financial statements.

    Appropriateness (of audit evidence) - The measure of the quality of audit evidence; that is, its relevance and its reliability in providing support for the conclusions on which the auditor's opinion is based.

    Arm's length transaction - A transaction conducted on such terms and conditions as between a willing buyer and a willing seller who are unrelated and are acting independently of each other and pursuing their own best interests.

    Assertions - Representations by management, explicit or otherwise, that are embodied in the financial statements, as used by the auditor to consider the different types of potential misstatements that may occur. In the context of HKSAE 3410, assertions are defined as representations by the entity, explicit or otherwise, that are embodied in the GHG statement, as used by the practitioner to consider the different types of potential misstatements that may occur.

    Assess - Analyze identified risks of material misstatement to conclude on their significance. "Assess", by convention, is used only in relation to risk.

    Assurance - (see Reasonable assurance)

    Assurance engagement - An engagement in which a practitioner aims to obtain sufficient appropriate evidence in order to express a conclusion designed to enhance the degree of confidence of the intended users other than the responsible party about the subject matter information (that is, the outcome of the measurement or evaluation of an underlying subject matter against criteria). Each assurance engagement is classified on two dimensions:

    (i) Either a reasonable assurance engagement or a limited assurance engagement:

  • Reasonable assurance engagement - An assurance engagement in which the practitioner reduces engagement risk to an acceptably low level in the circumstances of the engagement as the basis for the practitioner's conclusion. The practitioner's conclusion is expressed in a form that conveys the practitioner's opinion on the outcome of the measurement or evaluation of the underlying subject matter against criteria.
  • Limited assurance engagement - An assurance engagement in which the practitioner reduces engagement risk to a level that is acceptable in the circumstances of the engagement but where that risk is greater than for a reasonable assurance engagement as the basis for expressing a conclusion in a form that conveys whether, based on the procedures performed and evidence obtained, a matter(s) has come to the practitioner's attention to cause the practitioner to believe the subject matter information is materially misstated.
  • (ii) Either an attestation engagement or a direct engagement:

  • Attestation engagement - An assurance engagement in which a party other than the practitioner measures or evaluates the underlying subject matter against the criteria.
  • Direct engagement - An assurance engagement in which the practitioner measures or evaluates the underlying subject matter against the applicable criteria and the practitioner presents the resulting subject matter information as part of, or accompanying, the assurance report.
  • Assurance engagement risk - The risk that the practitioner expresses an inappropriate conclusion when the subject matter information is materially misstated.

    Assurance skills and techniques - Those planning, evidence gathering, evidence evaluation, communication and reporting skills and techniques demonstrated by an assurance practitioner that are distinct from expertise in the underlying subject matter of any particular assurance engagement or its measurement or evaluation.

    Audit documentation - The record of audit procedures performed, relevant audit evidence obtained, and conclusions the auditor reached (terms such as "working papers" or "workpapers" are also sometimes used).

    Audit evidence - Information used by the auditor in arriving at the conclusions on which the auditor's opinion is based. Audit evidence includes both information contained in the accounting records underlying the financial statements and other information.

    Audit file - One or more folders or other storage media, in physical or electronic form, containing the records that comprise the audit documentation for a specific engagement.

    Audit firm - (see Firm)

    Audit opinion - (see Modified opinion and Unmodified opinion)

    Audit risk - The risk that the auditor expresses an inappropriate audit opinion when the financial statements are materially misstated. Audit risk is a function of the risks of material misstatement and detection risk.

    Audit sampling (sampling) - The application of audit procedures to less than 100% of items within a population of audit relevance such that all sampling units have a chance of selection in order to provide the auditor with a reasonable basis on which to draw conclusions about the entire population.

    Audited financial statements (in the context of HKSA 810 (Revised)) - Financial statements audited by the auditor in accordance with HKSAs, and from which the summary financial statements are derived.

    Auditor - "Auditor" is used to refer to the person or persons conducting the audit, usually the engagement partner or other members of the engagement team, or, as applicable, the firm. Where an HKSA expressly intends that a requirement or responsibility be fulfilled by the engagement partner, the term "engagement partner" rather than "auditor" is used.

    Auditor association with financial information - An auditor is associated with financial information when the auditor attaches a report to that information or consents to the use of the auditor's name in a professional connection.

    Auditor's expert - An individual or organization possessing expertise in a field other than accounting or auditing, whose work in that field is used by the auditor to assist the auditor in obtaining sufficient appropriate audit evidence. An auditor's expert may be either an auditor's internal expert (who is a partner or staff, including temporary staff, of the auditor's firm or a network firm), or an auditor's external expert.

    Auditor's point estimate or auditor's range - An amount, or range of amounts, respectively, developed by the auditor in evaluating management's point estimate.

    Base year - A specific year or an average over multiple years against which an entity's emissions are compared over time.

    Business risk - A risk resulting from significant conditions, events, circumstances, actions or inactions that could adversely affect an entity's ability to achieve its objectives and execute its strategies, or from the setting of inappropriate objectives and strategies.

    Cap and trade - A system that sets overall emissions limits, allocates emissions allowances to participants, and allows them to trade allowances and emission credits with each other.

    Carve-out method - Method of dealing with the services provided by a subservice organization, whereby the service organization's description of its system includes the nature of the services provided by a subservice organization, but that subservice organization's relevant control objectives and related controls are excluded from the service organization's description of its system and from the scope of the service auditor's engagement.

    Comparative financial statements - Comparative information where amounts and other disclosures for the prior period are included for comparison with the financial statements of the current period but, if audited, are referred to in the auditor's opinion.

    Comparative information - The amounts and disclosures included in the financial statements in respect of one or more prior periods in accordance with the applicable financial reporting framework.

    Compilation engagement - An engagement in which a practitioner applies accounting and financial reporting expertise to assist management in the preparation and presentation of financial information of an entity in accordance with an applicable financial reporting framework, and reports as required by this HKSRS.

    Complementary user entity controls - Controls that the service organization assumes, in the design of its service, will be implemented by user entities, and which, if necessary to achieve control objectives, are identified in the description of its system.

    Component - An entity or business activity for which group or component management prepares financial information that should be included in the group financial statements.

    Component auditor - An auditor who, at the request of the group engagement team, performs work on financial information related to a component for the group audit.

    Component management - Management responsible for the preparation of the financial information of a component.

    Component materiality - The materiality for a component determined by the group engagement team.

    Computer-assisted audit techniques - Applications of auditing procedures using the computer as an audit tool (also known as CAATs).

    Control activities - Those policies and procedures that help ensure that management directives are carried out. Control activities are a component of internal control.

    Control environment - Includes the governance and management functions and the attitudes, awareness and actions of those charged with governance and management concerning the entity's internal control and its importance in the entity. The control environment is a component of internal control.

    Control objective - The aim or purpose of a particular aspect of controls. Control objectives relate to risks that controls seek to mitigate.

    Control risk - (see Risk of material misstatement)

    Controls at the service organization - Controls over the achievement of a control objective that is covered by the service auditor's assurance report.

    Controls at a subservice organization - Controls at a subservice organization to provide reasonable assurance about the achievement of a control objective.

    Corporate governance - (see Governance)

    Corresponding figures - Comparative information where amounts and other disclosures for the prior period are included as an integral part of the current period financial statements, and are intended to be read only in relation to the amounts and other disclosures relating to the current period (referred to as "current period figures").

    Criteria - The benchmarks used to measure or evaluate the underlying subject matter. The "applicable criteria" are the criteria used for the particular engagement.

    Date of approval of the financial statements - The date on which all the statements that comprise the financial statements, including the related notes, have been prepared and those with the recognized authority have asserted that they have taken responsibility for those financial statements.

    Date of report (in relation to quality control) - The date selected by the practitioner to date the report.

    Date of the auditor's report - The date the auditor dates the report on the financial statements in accordance with HKSA 700 (Revised).

    Date of the financial statements - The date of the end of the latest period covered by the financial statements.

    Date the financial statements are issued - The date that the auditor's report and audited financial statements are made available to third parties.

    Deficiency in internal control - This exists when:

    (a) A control is designed, implemented or operated in such a way that it is unable to prevent, or detect and correct, misstatements in the financial statements on a timely basis; or

    (b) A control necessary to prevent, or detect and correct, misstatements in the financial statements on a timely basis is missing.

    Detection risk - The risk that the procedures performed by the auditor to reduce audit risk to an acceptably low level will not detect a misstatement that exists and that could be material, either individually or when aggregated with other misstatements.

    Direct assistance - The use of internal auditors to perform audit procedures under the direction, supervision and review of the external auditor.

    Element - (see Element of a financial statement)

    Element of a financial statement (in the context of HKSA 805 (Revised)) - An element, account or item of a financial statement.

    Emissions - The GHGs that, during the relevant period, have been emitted to the atmosphere or would have been emitted to the atmosphere had they not been captured and channeled to a sink. Emissions can be categorized as:

  • Direct emissions (also known as Scope 1 emissions), which are emissions from sources that are owned or controlled by the entity.
  • Indirect emissions, which are emissions that are a consequence of the activities of the entity, but which occur at sources that are owned or controlled by another entity. Indirect emissions can be further categorized as:
  • Scope 2 emissions, which are emissions associated with energy that is transferred to and consumed by the entity.
  • Scope 3 emissions, which are all other indirect emissions.
  • Emissions deduction - Any item included in the entity's GHG statement that is deducted from the total reported emissions, but which is not a removal; it commonly includes purchased offsets, but can also include a variety of other instruments or mechanisms such as performance credits and allowances that are recognized by a regulatory or other scheme of which the entity is a part.

    Emissions factor - A mathematical factor or ratio for converting the measure of an activity (for example, liters of fuel consumed, kilometers travelled, the number of animals in husbandry, or tonnes of product produced) into an estimate of the quantity of GHGs associated with that activity.

    Emissions trading scheme - A market-based approach used to control greenhouse gases by providing economic incentives for achieving reductions in the emissions of such gases.

    Emphasis of Matter paragraph - A paragraph included in the auditor's report that refers to a matter appropriately presented or disclosed in the financial statements that, in the auditor's judgment, is of such importance that it is fundamental to users' understanding of the financial statements.

    Engagement circumstances - The broad context defining the particular engagement, which includes: the terms of the engagement; whether it is a reasonable assurance engagement or a limited assurance engagement, the characteristics of the underlying subject matter; the measurement or evaluation criteria; the information needs of the intended users; relevant characteristics of the responsible party, the measurer or evaluator, and the engaging party and their environment; and other matters, for example events, transactions, conditions and practices, that may have a significant effect on the engagement.

    Engagement documentation - The record of work performed, results obtained, and conclusions the practitioner reached (terms such as "working papers" or "workpapers" are sometimes used).

    Engagement letter - Written terms of an engagement in the form of a letter.

    Engagement partner - The partner or other person in the firm who is responsible for the engagement and its performance, and for the report that is issued on behalf of the firm, and who, where required, has the appropriate authority from a professional, legal or regulatory body.

    Engagement quality control review - A process designed to provide an objective evaluation, on or before the date of the report, of the significant judgments the engagement team made and the conclusions it reached in formulating the report. The engagement quality control review process is for audits of financial statements of listed entities and those other engagements, if any, for which the firm has determined an engagement quality control review is required.

    Engagement quality control reviewer - A partner, other person in the firm, suitably qualified external person, or a team made up of such individuals, none of whom is part of the engagement team, with sufficient and appropriate experience and authority to objectively evaluate the significant judgments the engagement team made and the conclusions it reached in formulating the report.

    Engagement risk - The risk that the practitioner expresses an inappropriate conclusion when the subject matter information is materially misstated.

    Engagement team - All partners and staff performing the engagement, and any individuals engaged by the firm or a network firm who perform procedures on the engagement. This excludes an auditor's external expert engaged by the firm or by a network firm.

    Engagement team (in the context of HKSAE 3000 (Revised)) - All partners and staff performing the engagement, and any individuals engaged by the firm or a network firm who perform procedures on the engagement. This excludes a practitioner's external expert engaged by the firm or a network firm.

    Engaging party - The party(ies) that engages the practitioner to perform the assurance engagement.

    Entity (in the context of HKSAE 3410) - The legal entity, economic entity, or the identifiable portion of a legal or economic entity (for example, a single factory or other form of facility, such as a land fill site), or combination of legal or other entities or portions of those entities (for example, a joint venture) to which the emissions in the GHG statement relate.

    Entity's risk assessment process - A component of internal control that is the entity's process for identifying business risks relevant to financial reporting objectives and deciding about actions to address those risks, and the results thereof.

    Environmental risk - In certain circumstances, factors relevant to the assessment of inherent risk for the development of the overall audit plan may include the risk of material misstatement of the financial statements due to environmental matters.

    Error - An unintentional misstatement in financial statements, including the omission of an amount or a disclosure.

    Estimation uncertainty - Susceptibility to an inherent lack of precision in measurement.

    Evaluate - Identify and analyze the relevant issues, including performing further procedures as necessary, to come to a specific conclusion on a matter. "Evaluation", by convention, is used only in relation to a range of matters, including evidence, the results of procedures and the effectiveness of management's response to a risk.

    Evidence - Information used by the practitioner in arriving at the practitioner's conclusion. Evidence includes both information contained in relevant information systems, if any, and other information. For purposes of the HKSAEs:

    (i) Sufficiency of evidence is the measure of the quantity of evidence.

    (ii) Appropriateness of evidence is the measure of the quality of evidence.

    Exception - A response that indicates a difference between information requested to be confirmed, or contained in the entity's records, and information provided by the confirming party.

    Experienced auditor - An individual (whether internal or external to the firm) who has practical audit experience, and a reasonable understanding of:

    (a) Audit processes;

    (b) HKSAs and applicable legal and regulatory requirements;

    (c) The business environment in which the entity operates; and

    (d) Auditing and financial reporting issues relevant to the entity's industry.

    Expert - (see Auditor's expert and Management's expert)

    Expertise - Skills, knowledge and experience in a particular field.

    External confirmation - Audit evidence obtained as a direct written response to the auditor from a third party (the confirming party), in paper form, or by electronic or other medium.

    Fair presentation framework - (see Applicable financial reporting framework and General purpose framework)

    Financial statements - A structured representation of historical financial information, including disclosures, intended to communicate an entity's economic resources or obligations at a point in time or the changes therein for a period of time in accordance with a financial reporting framework.

    Firm - A sole practitioner, partnership or corporation or other entity of professional accountants. "Firm" should be read as referring to its public sector equivalents where relevant.

    Forecast - Prospective financial information prepared on the basis of assumptions as to future events which management expects to take place and the actions management expects to take as of the date the information is prepared (best-estimate assumptions).

    Fraud - An intentional act by one or more individuals among management, those charged with governance, employees, or third parties, involving the use of deception to obtain an unjust or illegal advantage.

    Fraud risk factors - Events or conditions that indicate an incentive or pressure to commit fraud or provide an opportunity to commit fraud.

    Fraudulent financial reporting - Involves intentional misstatements, including omissions of amounts or disclosures in financial statements, to deceive financial statement users.

    Further procedures - Procedures performed in response to assessed risks of material misstatement, including tests of controls (if any), tests of details and analytical procedures.

    General IT-controls - Policies and procedures that relate to many applications and support the effective functioning of application controls by helping to ensure the continued proper operation of information systems.

    General purpose financial statements - Financial statements prepared in accordance with a general purpose framework.

    General purpose framework - A financial reporting framework designed to meet the common financial information needs of a wide range of users. The financial reporting framework may be a fair presentation framework or a compliance framework.

    GHG statement - A statement setting out constituent elements and quantifying an entity's GHG emissions for a period (sometimes known as an emissions inventory) and, where applicable, comparative information and explanatory notes including a summary of significant quantification and reporting policies.

    Greenhouse gases (GHGs) - Carbon dioxide (CO2) and any other gases required by the applicable criteria to be included in the GHG statement, such as: methane; nitrous oxide; sulfur hexafluoride; hydrofluorocarbons; perfluorocarbons; and chlorofluorocarbons.

    Governance - Describes the role of person(s) or organization(s) with responsibility for overseeing the strategic direction of the entity and obligations related to the accountability of the entity.

    Group - All the components whose financial information is included in the group financial statements. A group always has more than one component.

    Group audit - The audit of group financial statements.

    Group audit opinion - The audit opinion on the group financial statements.

    Group engagement partner - The partner or other person in the firm who is responsible for the group audit engagement and its performance, and for the auditor's report on the group financial statements that is issued on behalf of the firm.

    Group engagement team - Partners, including the group engagement partner, and staff who establish the overall group audit strategy, communicate with component auditors, perform work on the consolidation process, and evaluate the conclusions drawn from the audit evidence as the basis for forming an opinion on the group financial statements.

    Group financial statements - Financial statements that include the financial information of more than one component. The term "group financial statements" also refers to combined financial statements aggregating the financial information prepared by components that have no parent but are under common control.

    Group management - Management responsible for the preparation of the group financial statements.

    Group-wide controls - Controls designed, implemented and maintained by group management over group financial reporting.

    Historical financial information - Information expressed in financial terms in relation to a particular entity, derived primarily from that entity's accounting system, about economic events occurring in past time periods or about economic conditions or circumstances at points in time in the past.

    Inclusive method - Method of dealing with the services provided by a subservice organization, whereby the service organization's description of its system includes the nature of the services provided by a subservice organization, and that subservice organization's relevant control objectives and related controls are included in the service organization's description of its system and in the scope of the service auditor's engagement.

    Independence - Comprises:

    (a) Independence of mind - the state of mind that permits the expression of an opinion without being affected by influences that compromise professional judgment, thereby allowing an individual to act with integrity, and exercise objectivity and professional skepticism.

    (b) Independence in appearance - the avoidance of facts and circumstances that are so significant that a reasonable and informed third party would be likely to conclude that a firm's, or an audit or assurance team member's, integrity, objectivity or professional skepticism has been compromised.

    Information system relevant to financial reporting - A component of internal control that includes the financial reporting system, and consists of the procedures and records established to initiate, record, process and report entity transactions (as well as events and conditions) and to maintain accountability for the related assets, liabilities and equity.

    Inherent risk - (see Risk of material misstatement)

    Initial audit engagement - An engagement in which either:

    (a) The financial statements for the prior period were not audited; or

    (b) The financial statements for the prior period were audited by a predecessor auditor.

    Inquiry - Inquiry consists of seeking information of knowledgeable persons, both financial and non-financial, within the entity or outside the entity.

    Inquiry (in the context of HKSRE 2400 (Revised)) - Inquiry consists of seeking information of knowledgeable persons from within or outside the entity.

    Inspection (as an audit procedure) - Examining records or documents, whether internal or external, in paper form, electronic form, or other media, or a physical examination of an asset.

    Inspection (in relation to quality control) - In relation to completed engagements, procedures designed to provide evidence of compliance by engagement teams with the firm's quality control policies and procedures.

    Intended users - The individual(s) or organization(s), or group(s) thereof that the practitioner expects will use the assurance report.

    Interim financial information or statements - Financial information (which may be less than a complete set of financial statements as defined above) issued at interim dates (usually half-yearly or quarterly) in respect of a financial period.

    Internal audit function - A function of an entity that performs assurance and consulting activities designed to evaluate and improve the effectiveness of the entity's governance, risk management and internal control processes.

    Internal auditors - Those individuals who perform the activities of the internal audit function.

    Internal control - The process designed, implemented and maintained by those charged with governance, management and other personnel to provide reasonable assurance about the achievement of an entity's objectives with regard to reliability of financial reporting, effectiveness and efficiency of operations, and compliance with applicable laws and regulations.

    International Financial Reporting Standards - The International Financial Reporting Standards issued by the International Accounting Standards Board.

    Investigate - Inquire into matters arising from other procedures to resolve them.

    IT environment - The policies and procedures that the entity implements and the IT infrastructure (hardware, operating systems, etc.) and application software that it uses to support business operations and achieve business strategies.

    Key audit matters - Those matters that, in the auditor's professional judgment, were of most significance in the audit of the financial statements of the current period. Key audit matters are selected from matters communicated with those charged with governance.

    Limited assurance (in the context of HKSRE 2400 (Revised)) - The level of assurance obtained where engagement risk is reduced to a level that is acceptable in the circumstances of the engagement, but where that risk is greater than for a reasonable assurance engagement, as the basis for expressing a conclusion in accordance with this HKSRE.

    Limited assurance engagement - (see Assurance engagement)

    Listed entity - An entity whose shares, stock or debt are quoted or listed on a recognized stock exchange, or are marketed under the regulations of a recognized stock exchange or other equivalent body.

    Management - The person(s) with executive responsibility for the conduct of the entity's operations.

    Management bias - A lack of neutrality by management in the preparation of information.

    Management's expert - An individual or organization possessing expertise in a field other than accounting or auditing, whose work in that field is used by the entity to assist the entity in preparing the financial statements.

    Management's point estimate - The amount selected by management for recognition or disclosure in the financial statements as an accounting estimate.

    Measurer or evaluator - The party(ies) who measures or evaluates the underlying subject matter against the criteria.

    Misappropriation of assets - Involves the theft of an entity's assets and is often perpetrated by employees in relatively small and immaterial amounts.

    Misstatement - A difference between the reported amount, classification, presentation, or disclosure of a financial statement item and the amount, classification, presentation, or disclosure that is required for the item to be in accordance with the applicable financial reporting framework. Misstatements can arise from error or fraud.

    Misstatement of fact (with respect to other information) (in the context of HKSAE 3000 (Revised)) - Other information that is unrelated to matters appearing in the subject matter information or the assurance report that is incorrectly stated or presented.

    Misstatement of the other information - A misstatement of the other information exists when the other information is incorrectly stated or otherwise misleading (including because it omits or obscures information necessary for a proper understanding of a matter disclosed in the other information).

    Modified opinion - A qualified opinion, an adverse opinion or a disclaimer of opinion on the financial statements.

    Monitoring (in relation to quality control) - A process comprising an ongoing consideration and evaluation of the firm's system of quality control, including a periodic inspection of a selection of completed engagements, designed to provide the firm with reasonable assurance that its system of quality control is operating effectively.

    Monitoring of controls - A process to assess the effectiveness of internal control performance over time.

    Negative confirmation request - A request that the confirming party respond directly to the auditor only if the confirming party disagrees with the information provided in the request.

    Network - A larger structure:

    (a) That is aimed at cooperation, and

    (b) That is clearly aimed at profit or cost-sharing or shares common ownership, control or management, common quality control policies and procedures, common business strategy, the use of a common brand name, or a significant part of professional resources.

    Network firm - A firm or entity that belongs to a network.

    Non-compliance (in the context of HKSA 250 (Revised)) - Acts of omission or commission by the entity, either intentional or unintentional, which are contrary to the prevailing laws or regulations.

    Non-response - A failure of the confirming party to respond, or fully respond, to a positive confirmation request, or a confirmation request returned undelivered.

    Non-sampling risk - The risk that the auditor reaches an erroneous conclusion for any reason not related to sampling risk.

    Observation - Consists of looking at a process or procedure being performed by others, for example, the auditor's observation of inventory counting by the entity's personnel, or of the performance of control activities.

    Opening balances - Those account balances that exist at the beginning of the period. Opening balances are based upon the closing balances of the prior period and reflect the effects of transactions and events of prior periods and accounting policies applied in the prior period.

    Organizational boundary - The boundary that determines which operations to include in the entity's GHG statement.

    Other information - Financial or non-financial information (other than financial statements and the auditor's report thereon) included in an entity's annual report.

    Other information (in the context of HKSAE 3000 (Revised)) - Information (other than the subject matter information and the assurance report thereon) which is included, either by law, regulation or custom, in a document containing the subject matter information and the assurance report thereon.

    Other Matter paragraph - A paragraph included in the auditor's report that refers to a matter other than those presented or disclosed in the financial statements that, in the auditor's judgment, is relevant to users' understanding of the audit, the auditor's responsibilities or the auditor's report.

    Outcome of an accounting estimate - The actual monetary amount that results from the resolution of the transaction(s), event(s) or condition(s) addressed by an accounting estimate.

    Overall audit strategy - Sets the scope, timing and direction of the audit, and guides the development of the more detailed audit plan.

    Partner - Any individual with authority to bind the firm with respect to the performance of a professional services engagement.

    Performance materiality - The amount or amounts set by the auditor at less than materiality for the financial statements as a whole to reduce to an appropriately low level the probability that the aggregate of uncorrected and undetected misstatements exceeds materiality for the financial statements as a whole.

    Personnel - Partners and staff.

    Pervasive - A term used, in the context of misstatements, to describe the effects on the financial statements of misstatements or the possible effects on the financial statements of misstatements, if any, that are undetected due to an inability to obtain sufficient appropriate audit evidence.

    Population - The entire set of data from which a sample is selected and about which the auditor wishes to draw conclusions.

    Positive confirmation request - A request that the confirming party respond directly to the auditor indicating whether the confirming party agrees or disagrees with the information in the request, or providing the requested information.

    Practitioner - A professional accountant in public practice.

    Practitioner (in the context of HKSAE 3000 (Revised)) - The individual(s) conducting the engagement (usually the engagement partner or other members of the engagement team, or, as applicable, the firm).

    Practitioner (in the context of HKSRE 2400 (Revised)) - A professional accountant in public practice. The term includes the engagement partner or other members of the engagement team, or, as applicable, the firm.

    Practitioner (in the context of HKSRS 4410 (Revised)) - A professional accountant in public practice who conducts the compilation engagement.

    Practitioner's expert - An individual or organization possessing expertise in a field other than assurance, whose work in that field is used by the practitioner to assist the practitioner in obtaining sufficient appropriate evidence.

    Preconditions for an audit - The use by management of an acceptable financial reporting framework in the preparation of the financial statements and the agreement of management and, where appropriate, those charged with governance to the premise on which an audit is conducted.

    Predecessor auditor - The auditor from a different audit firm, who audited the financial statements of an entity in the prior period and who has been replaced by the current auditor.

    Premise, relating to the responsibilities of management and, where appropriate, those charged with governance, on which an audit is conducted - That management and, where appropriate, those charged with governance have acknowledged and understand that they have the following responsibilities:

    (a) For the preparation of the financial statements in accordance with the applicable financial reporting framework;

    (b) For such internal control as management and, where appropriate, those charged with governance determine is necessary to enable the preparation of financial statements that are free from material misstatement; and

    (c) To provide the auditor with access to all information, additional information that the auditor may request, and unrestricted access to persons within the entity.

    Pro forma adjustments - In relation to unadjusted financial information, these include:

    (a) Adjustments to unadjusted financial information that illustrate the impact of a significant event or transaction as if the event had occurred or the transaction had been undertaken at an earlier date selected for purposes of the illustration; and

    (b) Adjustments to unadjusted financial information that are necessary for the pro forma financial information to be compiled on a basis consistent with the applicable financial reporting framework of the reporting entity and its accounting policies under that framework.

    Pro forma financial information - Financial information shown together with adjustments to illustrate the impact of an event or transaction on unadjusted financial information as if the event had occurred or the transaction had been undertaken at an earlier date selected for purposes of the illustration.

    Professional accountant - An individual who is a member of the Hong Kong Institute of Certified Public Accountants.

    Professional accountant in public practice - A professional accountant, irrespective of functional classification (for example, audit, tax or consulting) in a firm that provides professional services.

    Professional judgment - The application of relevant training, knowledge and experience, within the context provided by auditing, accounting and ethical standards, in making informed decisions about the courses of action that are appropriate in the circumstances of the audit engagement.

    Professional judgment (in the context of HKSAE 3000 (Revised)) - The application of relevant training, knowledge and experience, within the context provided by assurance and ethical standards, in making informed decisions about the courses of action that are appropriate in the circumstances of the engagement.

    Professional judgment (in the context of HKSRE 2400 (Revised)) - The application of relevant training, knowledge and experience, within the context provided by assurance, accounting and ethical standards, in making informed decisions about the courses of action that are appropriate in the circumstances of the review engagement.

    Professional skepticism - An attitude that includes a questioning mind, being alert to conditions which may indicate possible misstatement due to error or fraud, and a critical assessment of evidence.

    Professional skepticism (in the context of HKSAE 3000 (Revised)) - An attitude that includes a questioning mind, being alert to conditions which may indicate possible misstatement, and a critical assessment of evidence.

    Professional standards - Hong Kong Standards on Auditing (HKSAs) and relevant ethical requirements.

    Professional standards (in the context of HKSQC 1) - Hong Kong Engagement Standards, as defined in the Amended Preface to the Hong Kong Quality Control, Auditing, Review, Other Assurance, and Related Services Pronouncements, and relevant ethical requirements.

    Projection - Prospective financial information prepared on the basis of:

    (a) Hypothetical assumptions about future events and management actions which are not necessarily expected to take place; or

    (b) A mixture of best-estimate and hypothetical assumptions.

    Prospective financial information - Financial information based on assumptions about events that may occur in the future and possible actions by an entity.

    Prospectus - A document issued pursuant to legal or regulatory requirements relating to the entity's securities on which it is intended that a third party should make an investment decision.

    Public sector - National governments, regional (for example, state, provincial, territorial) governments, local (for example, city, town) governments and related governmental entities (for example, agencies, boards, commissions and enterprises).

    Published financial information - Financial information of the entity or of an acquiree or a divestee that is made available publicly.

    Purchased offset - An emissions deduction in which the entity pays for the lowering of another entity's emissions (emissions reductions) or the increasing of another entity's removals (removal enhancements), compared to a hypothetical baseline.

    Quantification - The process of determining the quantity of GHGs that relate to the entity, either directly or indirectly, as emitted (or removed) by particular sources (or sinks).

    Reasonable assurance (in the context of audit engagements, and in quality control) - A high, but not absolute, level of assurance.

    Reasonable assurance engagement - (see Assurance engagement)

    Recalculation - Consists of checking the mathematical accuracy of documents or records.

    Related party - A party that is either:

    (a) A related party as defined in the applicable financial reporting framework; or

    (b) Where the applicable financial reporting framework establishes minimal or no related party requirements:

    (i) A person or other entity that has control or significant influence over the reporting entity;

    (ii) Another entity over which the reporting entity has control or significant influence; or

    (iii) Another entity that is under common control with the reporting entity.

    Related services - Comprise agreed-upon procedures and compilations.

    Relevant ethical requirements (in the context of HKSQC 1) - Ethical requirements to which the engagement team and engagement quality control reviewer are subject when undertaking audits or reviews of financial statements, or other assurance or related services engagements.

    Relevant ethical requirements (in the context of the HKSAs) - Ethical requirements to which the engagement team and engagement quality control reviewer are subject when undertaking an audit engagement.

    Relevant ethical requirements (in the context of HKSRE 2400 (Revised)) - Ethical requirements to which the engagement team is subject when undertaking a review engagement.

    Relevant ethical requirements (in the context of HKSRS 4410 (Revised)) - Ethical requirements to which the engagement team is subject when undertaking a compilation engagement.

    Removal - The GHGs that the entity has, during the period, removed from the atmosphere, or that would have been emitted to the atmosphere had they not been captured and channeled to a sink.

    Reperformance - The auditor's independent execution of procedures or controls that were originally performed as part of the entity's internal controls.

    Report on the description and design of controls at a service organization (referred to in HKSA 402 as a type 1 report) - A report that comprises:

    (a) A description, prepared by management of the service organization, of the service organization's system, control objectives and related controls that have been designed and implemented as at a specified date; and

    (b) A report by the service auditor with the objective of conveying reasonable assurance that includes the service auditor's opinion on the description of the service organization's system, control objectives and related controls and the suitability of the design of the controls to achieve the specified control objectives.

    Report on the description and design of controls at a service organization (referred to in HKSAE 3402 as a "type 1 report")(in the context of HKSAE 3402) - A report that comprises:

    (a) The service organization's description of its system;

    (b) A written statement by the service organization that, in all material respects, and based on suitable criteria:

    (i) The description fairly presents the service organization's system as designed and implemented as at the specified date;

    (ii) The controls related to the control objectives stated in the service organization's description of its system were suitably designed as at the specified date; and

    (c) A service auditor's assurance report that conveys a reasonable assurance conclusion about the matters in (b)(i)-(ii) above.

    Report on the description, design, and operating effectiveness of controls at a service organization (referred to in HKSA 402 as a type 2 report) - A report that comprises:

    (a) A description, prepared by management of the service organization, of the service organization's system, control objectives and related controls, their design and implementation as at a specified date or throughout a specified period and, in some cases, their operating effectiveness throughout a specified period; and

    (b) A report by the service auditor with the objective of conveying reasonable assurance that includes:

    (i) The service auditor's opinion on the description of the service organization's system, control objectives and related controls, the suitability of the design of the controls to achieve the specified control objectives, and the operating effectiveness of the controls; and

    (ii) A description of the service auditor's tests of the controls and the results thereof.

    Report on the description, design and operating effectiveness of controls at a service organization (referred to in HKSAE 3402 as a "type 2 report") (in the context of HKSAE 3402) - A report that comprises:

    (a) The service organization's description of its system;

    (b) A written statement by the service organization that, in all material respects, and based on suitable criteria:

    (i) The description fairly presents the service organization's system as designed and implemented throughout the specified period;

    (ii) The controls related to the control objectives stated in the service organization's description of its system were suitably designed throughout the specified period; and

    (iii) The controls related to the control objectives stated in the service organization's description of its system operated effectively throughout the specified period; and

    (c) A service auditor's assurance report that:

    (i) Conveys a reasonable assurance conclusion about the matters in (b)(i)-(iii) above; and

    (ii) Includes a description of the tests of controls and the results thereof.

    Responsible party - The party(ies) responsible for the underlying subject matter.

    Review (in relation to quality control) - Appraising the quality of the work performed and conclusions reached by others.

    Review engagement - The objective of a review engagement is to enable an auditor to state whether, on the basis of procedures which do not provide all the evidence that would be required in an audit, anything has come to the auditor's attention that causes the auditor to believe that the financial statements are not prepared, in all material respects, in accordance with an applicable financial reporting framework.

    Review procedures - The procedures deemed necessary to meet the objective of a review engagement, primarily inquiries of entity personnel and analytical procedures applied to financial data.

    Risk assessment procedures - The audit procedures performed to obtain an understanding of the entity and its environment, including the entity's internal control, to identify and assess the risks of material misstatement, whether due to fraud or error, at the financial statement and assertion levels.

    Risk of material misstatement - The risk that the financial statements are materially misstated prior to audit. This consists of two components, described as follows at the assertion level:

    (a) Inherent risk - The susceptibility of an assertion about a class of transaction, account balance or disclosure to a misstatement that could be material, either individually or when aggregated with other misstatements, before consideration of any related controls.

    (b) Control risk - The risk that a misstatement that could occur in an assertion about a class of transaction, account balance or disclosure and that could be material, either individually or when aggregated with other misstatements, will not be prevented, or detected and corrected, on a timely basis by the entity's internal control.

    Risk of material misstatement (in the context of HKSAE 3000 (Revised)) - The risk that the subject matter information is materially misstated prior to the engagement.

    Sampling - (see Audit sampling)

    Sampling risk - The risk that the auditor's conclusion based on a sample may be different from the conclusion if the entire population were subjected to the same audit procedure. Sampling risk can lead to two types of erroneous conclusions:

    (a) In the case of a test of controls, that controls are more effective than they actually are, or in the case of a test of details, that a material misstatement does not exist when in fact it does.

    (b) In the case of a test of controls, that controls are less effective than they actually are, or in the case of a test of details, that a material misstatement exists when in fact it does not.

    Sampling unit - The individual items constituting a population.

    Scope of a review - The review procedures deemed necessary in the circumstances to achieve the objective of the review.

    Service auditor - An auditor who, at the request of the service organization, provides an assurance report on the controls of a service organization.

    Service auditor (in the context of HKSAE 3402) - A practitioner who, at the request of the service organization, provides an assurance report on controls of a service organization.

    Service organization - A third-party organization (or segment of a third-party organization) that provides services to user entities that are part of those entities' information systems relevant to financial reporting.

    Service organization (in the context of HKSAE 3402) - A third-party organization (or segment of a third-party organization) that provides services to user entities that are likely to be relevant to user entities' internal control as it relates to financial reporting.

    Service organization's statement - The written statement about the matters referred to in (b) of the definition of a report on the description, design and operating effectiveness of controls at a service organization (in the case of a type 2 report) or (b) of the definition of a report on the description and design of controls at a service organization (in the case of a type 1 report).

    Service organization's system - The policies and procedures designed, implemented and maintained by the service organization to provide user entities with the services covered by the service auditor's report.

    Service organization's system (or the system) (in the context of HKSAE 3402) - The policies and procedures designed and implemented by the service organization to provide user entities with the services covered by the service auditor's assurance report.

    Significance - The relative importance of a matter, taken in context. The significance of a matter is judged by the practitioner in the context in which it is being considered.

    Significant component - A component identified by the group engagement team (i) that is of individual financial significance to the group, or (ii) that, due to its specific nature or circumstances, is likely to include significant risks of material misstatement of the group financial statements.

    Significant deficiency in internal control - A deficiency or combination of deficiencies in internal control that, in the auditor's professional judgment, is of sufficient importance to merit the attention of those charged with governance.

    Significant facility - A facility that is of individual significance due to the size of its emissions relative to the aggregate emissions included in the GHG statement or its specific nature or circumstances which give rise to particular risks of material misstatement.

    Significant risk - An identified and assessed risk of material misstatement that, in the auditor's judgment, requires special audit consideration.

    Sink - A physical unit or process that removes GHGs from the atmosphere.

    Smaller entity - An entity which typically possesses qualitative characteristics such as:

    (a) Concentration of ownership and management in a small number of individuals; and

    (b) One or more of the following: straightforward or uncomplicated transactions; simple record-keeping; few lines of business and few products within business lines; few internal controls; few levels of management with responsibility for a broad range of controls; or few personnel, many having a wide range of duties.

    Source - A physical unit or process that releases GHGs into the atmosphere.

    Special purpose financial statements - Financial statements prepared in accordance with a special purpose framework.

    Special purpose framework - A financial reporting framework designed to meet the financial information needs of specific users.

    Staff - Professionals, other than partners, including any experts the firm employs.

    Statistical sampling - An approach to sampling that has the following characteristics:

    (a) Random selection of the sample items; and

    (b) The use of probability theory to evaluate sample results, including measurement of sampling risk.

    Stratification - The process of dividing a population into sub-populations, each of which is a group of sampling units which have similar characteristics (often monetary value).

    Subject matter information - The outcome of the measurement or evaluation of the underlying subject matter against the criteria, that is, the information that results from applying the criteria to the underlying subject matter.

    Subsequent events - Events occurring between the date of the financial statements and the date of the auditor's report, and facts that become known to the auditor after the date of the auditor's report.

    Subservice organization - A service organization used by another service organization to perform some of the services provided to user entities that are part of those user entities' information systems relevant to financial reporting.

    Subservice organization (in the context of HKSAE 3402) - A service organization used by another service organization to perform some of the services provided to user entities that are likely to be relevant to user entities' internal control as it relates to financial reporting.

    Substantive procedure - An audit procedure designed to detect material misstatements at the assertion level. Substantive procedures comprise:

    (a) Tests of details (of classes of transactions, account balances, and disclosures); and

    (b) Substantive analytical procedures.

    Sufficiency (of audit evidence) - The measure of the quantity of audit evidence. The quantity of the audit evidence needed is affected by the auditor's assessment of the risks of material misstatement and also by the quality of such audit evidence.

    Suitable criteria - (see Criteria)

    Suitably qualified external person - An individual outside the firm with the competence and capabilities to act as an engagement partner.

    Summary financial statements (in the context of HKSA 810 (Revised)) - Historical financial information that is derived from financial statements but that contains less detail than the financial statements, while still providing a structured representation consistent with that provided by the financial statements of the entity's economic resources or obligations at a point in time or the changes therein for a period of time.

    Supplementary information - Information that is presented together with the financial statements that is not required by the applicable financial reporting framework used to prepare the financial statements.

    Test - The application of procedures to some or all items in a population.

    Test of controls (in the context of HKSAE 3402) - A procedure designed to evaluate the operating effectiveness of controls in achieving the control objectives stated in the service organization's description of its system.

    Tests of controls - An audit procedure designed to evaluate the operating effectiveness of controls in preventing, or detecting and correcting, material misstatements at the assertion level.

    Those charged with governance - The person(s) or organization(s) (for example, a corporate trustee) with responsibility for overseeing the strategic direction of the entity and obligations related to the accountability of the entity.

    Tolerable misstatement - A monetary amount set by the auditor in respect of which the auditor seeks to obtain an appropriate level of assurance that the monetary amount set by the auditor is not exceeded by the actual misstatement in the population.

    Tolerable rate of deviation - A rate of deviation from prescribed internal control procedures set by the auditor in respect of which the auditor seeks to obtain an appropriate level of assurance that the rate of deviation set by the auditor is not exceeded by the actual rate of deviation in the population.

    Type of emission - A grouping of emissions based on, for example, source of emission, type of gas, region, or facility.

    Unadjusted financial information - Financial information of the entity to which pro forma adjustments are applied by the responsible party.

    Uncertainty - A matter whose outcome depends on future actions or events not under the direct control of the entity but that may affect the financial statements.

    Uncorrected misstatements - Misstatements that the auditor has accumulated during the audit and that have not been corrected.

    Underlying subject matter - The phenomenon that is measured or evaluated by applying criteria.

    Unmodified opinion - The opinion expressed by the auditor when the auditor concludes that the financial statements are prepared, in all material respects, in accordance with the applicable financial reporting framework.

    User auditor - An auditor who audits and reports on the financial statements of a user entity.

    User auditor (in the context of HKSAE 3402) - An auditor who audits and reports on the financial statements of a user entity.

    User entity - An entity that uses a service organization and whose financial statements are being audited.

    User entity (in the context of HKSAE 3402) - An entity that uses a service organization.

    Walk-through test - Involves tracing a few transactions through the financial reporting system.

    Written representation - A written statement by management provided to the auditor to confirm certain matters or to support other audit evidence.

    Key Takeaways Summary Table

    CategoryKey TermsImportant Notes
    Assurance EngagementsReasonable assurance, Limited assurance, Attestation, DirectTwo dimensions: level of assurance (reasonable vs limited) and type (attestation vs direct)
    Audit Risk ComponentsInherent risk, Control risk, Detection riskAudit risk = f(RMM, Detection risk); RMM = Inherent risk × Control risk
    Financial Reporting FrameworksFair presentation, ComplianceFair presentation allows departures; Compliance does not
    Internal ControlControl environment, Control activities, Risk assessment, Information system, MonitoringFive components of internal control
    SamplingStatistical, Non-statistical, Sampling risk, Non-sampling riskStatistical requires random selection and probability theory
    Service OrganizationsType 1 report, Type 2 report, Carve-out, InclusiveType 1 = design only; Type 2 = design and operating effectiveness
    GHG EmissionsScope 1, Scope 2, Scope 3, Direct, IndirectScope 1 = direct; Scope 2 = energy; Scope 3 = other indirect
    Quality ControlEngagement quality control review, Monitoring, InspectionFor listed entities and other specified engagements
    Opinion TypesUnmodified, Modified (Qualified, Adverse, Disclaimer)Modified when material misstatements or scope limitations exist
    Professional RequirementsProfessional judgment, Professional skepticism, IndependenceRequired attitude and mindset for all engagements

    Ad Space

    Traditional Chinese Section

    ❓ Ready to Test Your Knowledge?

    50 MCQs covering all sections. Timed at 1.25 min each (62.5 min total).

    📝 Start Q&A →🖨️ Save as PDF